2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-6278The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and...
CVE-2015-6012Multiple open redirect vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 20...
CVE-2015-6011Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allows remote attackers to conduc...
CVE-2015-6010Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-e...
CVE-2015-6009Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to e...
CVE-2015-6008install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands ...
CVE-2015-6007Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote atta...
CVE-2015-3974EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Accutrol, Bar-Tech Auto...
CVE-2015-6475Multiple cross-site scripting (XSS) vulnerabilities in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote atta...
CVE-2015-6474IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML s...
CVE-2015-6470Resource Data Management Data Manager before 2.2 allows remote authenticated users to modify arbitrary passwords via uns...
CVE-2015-6469The interpreter in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allows remote attackers to discover script source cod...
CVE-2015-6468Cross-site request forgery (CSRF) vulnerability in Resource Data Management Data Manager before 2.2 allows remote attack...
CVE-2015-6454Everest PeakHMI before 8.7.0.2, when the video server is used, allows remote attackers to cause a denial of service (inc...
CVE-2015-6306Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, ...
CVE-2015-6305Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne...
CVE-2015-6302The RADIUS functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.0(250.0) and 7.0(252.0) allows r...
CVE-2015-6282Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15...
CVE-2015-4543EMC RSA Archer GRC 5.x before 5.5.3 uses cleartext for stored passwords in unspecified circumstances, which allows remot...
CVE-2015-4542EMC RSA Archer GRC 5.x before 5.5.3 allows remote authenticated users to bypass intended access restrictions, and read o...
CVE-2015-4541Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.5.3 allow remote authenticated us...
CVE-2015-4540Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 6.8.1 P18 a...
CVE-2015-4539Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 7.0.0 allow...
CVE-2015-7375Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of...
CVE-2015-7374The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbit...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now